CVE-2022-34440: Critical severity dell policy manager for secure connect gateway vulnerability
Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability. An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerability to login to the system to gain admin privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-34440?
CVE-2022-34440 is classified as a high severity vulnerability due to the potential for unauthorized admin access.
How do I fix CVE-2022-34440?
To resolve CVE-2022-34440, update your Dell EMC SCG Policy Manager to version 5.14 or later.
What versions of Dell EMC SCG Policy Manager are affected by CVE-2022-34440?
Versions 5.10 to 5.12 of Dell EMC SCG Policy Manager are affected by CVE-2022-34440.
What can an attacker do with CVE-2022-34440?
An attacker exploiting CVE-2022-34440 could gain admin privileges through hard-coded cryptographic keys.
Is there a public disclosure for CVE-2022-34440?
Yes, CVE-2022-34440 has been publicly disclosed as part of Dell's security update documentation.